Field method
How we examine a control before we write a finding.
This page describes the working method behind our audits for fintech operators. It is the craft we bring to engagements—not a software methodology dressed in new clothes.
Map the money journey
We sketch the path funds take—customer or merchant onboarding, authorisation, settlement, refunds, and exceptions. The map stays short enough to discuss in one sitting and specific enough to name the systems of record your staff already use.
Walk the step, not the policy
Beside operations or compliance staff, we ask them to perform or narrate a recent case. Where the screen, the stamp, or the approval email diverges from the written control, we note the divergence as a candidate finding.
Sample with intent
Samples are drawn from populations you help define: settlement dates, product codes, alert types, or loan statuses. We avoid theatrical sample sizes; we choose enough items to test whether a control holds under ordinary pressure.
Rate and assign
Findings carry severity ratings tied to operational or regulatory consequence, plus a suggested owner role. We do not invent metrics for marketing; we write what a remediation meeting can use.
What the method refuses
- Checkbox questionnaires that never open a file
- Findings written only from policy binders
- Severity inflation to justify larger fees
- Vendor referrals tied to the engagement
Where to begin
If settlement breaks, loan overrides, or wallet alerts are already keeping your team late, start with the engagement that matches that pressure. The flagship Payments Control Audit remains the fullest expression of this method.